A browser-local medical appeal desk where agents get capabilities—not identity—with one-field consent, adversarial leak blocking, and an auditable disclosure ledger.
Aggregate38
Leverage10
Execution9
Impact9
Creativity10
Each criterion 1–10, equally weighted; aggregate is their sum. Ranking is the pipeline's consolidated output.
Origin, access model, eligibility, and substitution are reviewer diagnostics, not judging criteria. Authentication requirements are not penalized.
02 The two blind reviews
Two independent reviewers scored this project blind, from a sanitized evidence packet.
Scores are shown separately so the reasoning stays inspectable. A withheld score means the reviewers differed by more than two points.
Reviewer A (round 1)
confidence 80%
Leverage
9 /10
The live case, one-field consent, fail-closed disclosure boundary, and auditable ledger require shared page state and agent capabilities rather than opaque identity access; generic UI automation is materially less reliable.
Evidence cited
Seven narrow tools operate on browser-local IndexedDB case state.
Sensitive raw identifiers require one-time human allow/deny/expiry.
Seeded prompt injection is marked untrusted and attempted leakage is blocked.
Execution
8 /10
The packet describes a complete adversarial workflow and the frame sheets/promotional UI show a coherent appeal desk, though there is no transcript or live observation.
Evidence cited
Demo reported alive, public repository, and four frame sheets submitted.
Description covers evidence, policy, disclosure, draft, and export paths.
People appealing medical denials have a real need for document interpretation and drafting while facing serious exposure of identifiers and health information.
Evidence cited
Description names codes, deadlines, missing evidence, and sensitive identifiers.
Capability-not-identity model and auditable disclosure directly address the privacy risk.
Creativity
9 /10
The capability-not-identity framing and adversarial leak-blocking demonstration are original and deeply aligned with the agent medium.
Evidence cited
One-field consent is integrated into the tool interaction.
Prompt-injected request for member ID is treated as an explicit red-team boundary case.
Reviewer B (round 2)
confidence 79%
Leverage
8 /10
Structured, shared case state and explicit disclosure gates materially outperform generic UI driving for privacy-sensitive appeal work; the agent receives capabilities rather than identity.
Evidence cited
Seven narrow tools are described for evidence, line items, policy rules, scenarios, disclosure, drafting, and export.
Human and agent share a live case with one-field consent and a fail-closed adversarial demonstration.
Frame sheets show a structured appeal workspace, boundary/visibility states, and checkable defects.
Execution
7 /10
The packet presents a coherent, intentional workflow and substantial UI evidence, but no actual video transcript or final end-to-end runtime proof is supplied.
Evidence cited
Contact sheets show a rendered outpatient imaging appeal with structured metadata, warnings, workflow panels, and later privacy/defect views.
Devpost packaging describes browser-local state, consent, ledger, and tests, but the screenshot itself is promotional packaging.
Impact
8 /10
People appealing denied medical claims have a concrete high-stakes need for policy/evidence assistance without exposing identity; the privacy-aware workflow credibly addresses it using synthetic claims.
Evidence cited
Pitch identifies medical-claim appealers needing help with codes, deadlines, missing evidence, and policy rules.
The product explicitly separates useful capabilities from sensitive identifiers and records disclosure decisions.
Creativity
8 /10
The capability-not-identity framing, adversarial prompt-injection boundary test, and two-visibility appeal model are a fresh and memorable application of WebMCP.
Evidence cited
Seeded OCR prompt injection is used as a red-team scenario.
Frames show one letter with two visibility levels and an appeal built around checkable defects.
03 Review highlights
Standouts across reviewers
Excellent privacy threat model.
Concrete adversarial demonstration rather than generic privacy claims.
Capability-not-identity privacy model.
Fail-closed prompt-injection demonstration with explicit disclosure consent.
Auditable, shared case state.
Red flags
All claim data is synthetic and no transcript is supplied.
No submitted video or transcript; visual evidence is contact sheets and a promotional Devpost image.
Final real-world submission or claim resolution is not shown; data is synthetic.
04 Evidence
What each artifact proves is labeled on the artifact itself. A Devpost page capture is packaging evidence, not proof the product runs;
video frames are evidence from the submitted demo, not live verification.
Contact sheets from the ?s video the team submitted. This is what reviewers were shown;
it demonstrates the product in motion but is not independent verification.
· watch the original
EX-V1 Sheet 1 of 3 · reported video evidenceEX-V2 Sheet 2 of 3 · reported video evidenceEX-V3 Sheet 3 of 3 · reported video evidence